CVE-2017-11698: Buffer Overflow
Heap-based buffer overflow in the getpage function in lib/dbm/src/hpage.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.
Other sources
Mozilla Network Security Services (NSS), as used in Mozilla Firefox is vulnerable to a heap-based buffer overflow, caused by improper bounds checking by getpage() in 'lib/dbm/src/hpage.c. By using the NSS tool certutil and malformed cert8.db file, a local attacker could overflow a buffer and execute arbitrary code on the system with elevated privileges.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-11698?
CVE-2017-11698 is a vulnerability in Mozilla Network Security Services (NSS) that allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.
How severe is CVE-2017-11698?
CVE-2017-11698 has a severity rating of 7.8 (high).
How does CVE-2017-11698 manifest?
CVE-2017-11698 manifests as a heap-based buffer overflow in the __get_page function in lib/dbm/src/h_page.c.
What software is affected by CVE-2017-11698?
Mozilla Network Security Services (NSS) is affected by CVE-2017-11698.
How can CVE-2017-11698 be exploited?
CVE-2017-11698 can be exploited by using a crafted cert8.db file.